Skip to content
Trellix Tracks Five Cyber Campaigns Built to Evade Detection

Trellix Tracks Five Cyber Campaigns Built to Evade Detection

Cybermagazine September 10, 2026

Cybersecurity firm Trellix has released its latest SecondSight Threat Hunting Report examining five major campaigns observed during the first half of 2026.

These include activity linked to APT28 , Bitter APT, the DarkSword iOS exploit kit, JSCeal and the Axios npm supply chain attack.

These cases show how attackers are exploiting trusted infrastructure, all the while relying on new techniques designed to evade conventional detection.

“AI and automation let us process and correlate telemetry at a speed no human team could match on its own, but they don’t replace human curiosity,” says John Fokker , Vice President of Threat Intelligence Strategy at Trellix.

“This report walks through five campaigns from the first half of 2026, where AI worked alongside human curiosity to find what adversaries hoped would stay unseen.

“The combination of AI and human intelligence is exactly how our SecondSight threat hunters operate.”

APT28 and DarkSword campaigns expose sophisticated evasion

In January of 2026, a threat group called APT28 – also known as Fancy Bear and UAC-0001 – orchestrated a spear-phishing campaign targeting European government , defence and diplomatic organisations.

This report walks through five campaigns from the first half of 2026, where AI worked alongside human curiosity to find what adversaries hoped would stay unseen John Fokker, Vice President of Threat Intelligence Strategy at Trellix

This report walks through five campaigns from the first half of 2026, where AI worked alongside human curiosity to find what adversaries hoped would stay unseen

The report says that Trellix Email Security identified and blocked at least 29 malicious emails which were sent to targets in nine Eastern European nations.

The “weapon of choice” was a Microsoft Office OLE security feature bypass disclosed as CVE-2026-21509, which APT28 weaponised within just 24 hours of its public disclosure.

Malicious files arrived in .doc format although it was structurally RTF files, thereby bypassing conventional inspection.

The lures for each target were personalised – and ranged from weapons-smuggling alerts, military training invitations, EU/NATO diplomatic consultation requests and meteorological emergency bulletins.

They contained authentic government aesthetics, official letterheads, bilingual formatting and ministerial seals.

The cherry on top was the fact that these emails were sent from real, compromised government accounts, lending them a veneer of authenticity.

Once the attachment was opened, it triggered a prompt which reached out to the attacker-controlled infrastructure to pull a malicious LNK file that then loaded a first-stage DLL (Dynamic Link Library).

The campaign used multiple layers of evasion. One infection chain concealed malicious code inside a PNG image while using legitimate cloud storage for command and control.

Another installed a malicious Outlook file that silently forwarded emails to attacker-controlled addresses.

In a separate Russian state- campaign on 26 March 2026, the threat actor sent four spear-phishing emails against senior government and defence personnel at NATO-aligned organisations.

The payload was likely the infamous DarkSword iOS exploit kit , which if triggered, could deploy a JavaScript backdoor that can exfiltrate credentials, contacts, location and files.

The attackers impersonated Atlantic Council President Frederick Kempe and used targeted emails leading to pages that served harmless PDFs to automated scanners but deployed the exploit chain to real iPhone users in selected locations.

JSCeal hides inside legitimate Node.js runtime

The JSCeal campaign, which targeted organisations in Southeast Asia demonstrates how attackers can easily abuse legitimate development tools to conceal malware.

The campaign began with an encoded PowerShell command that fetched malicious components including a Node.js runtime alongside an encrypted application script.

The attackers then used Node.js to execute the compiled JavaScript payload, a cryptocurrency-focused stealer called JSCeal.

It included multiple layers of encryption, compression and obfuscation designed to frustrate static analysis and automated sandboxing, Trellix notes.

Trellix’s SecondSight report examines five major cyber campaigns observed during the first half of 2026

APT28 weaponised the CVE-2026-21509 vulnerability within 24 hours of its public disclosure, targeting European government, defence and diplomatic organisations

Trellix Email Security identified and blocked at least 29 malicious emails sent to targets across nine Eastern European nations

A separate DarkSword campaign involved four spear-phishing emails targeting senior government and defence personnel at NATO-aligned organisations on 26 March 2026

The JSCeal campaign targeted organisations in Southeast Asia, using Node.js to execute a compiled JavaScript payload and multiple layers of obfuscation to frustrate analysis

Trellix observed execution of malicious Axios npm packages in 3% of exposed environments before the compromised versions were removed

Trellix says the campaigns demonstrate the value of combining AI-powered telemetry analysis with human threat-hunting expertise, with John Fokker highlighting that AI and automation “don't replace human curiosity”

The report says that the suspected JSCeal information stealer can target browser passwords, session cookies and cryptocurrency wallet information, while also supporting keylogging, screen capture and the theft of other sensitive data.

The modular nature of the payload could also allow attackers to introduce additional malicious tools after gaining access.

Trellix investigators uncovered the activity by tracing an unusual process chain from encoded PowerShell to Node.js running from a suspicious, masquerading directory. That process lineage provided a stronger signal than the encoded command alone.

Axios supply chain attack puts software trust under scrutiny

The fifth campaign centred on the Axios npm supply chain compromise , which followed the takeover of a package maintainer account.

Two malicious versions of the widely used JavaScript package were published with a dependency that downloaded cross-platform remote access payloads.

Trellix observed execution in 3% of exposed environments before the malicious versions were removed.

Across the five investigations, a common pattern emerges: attackers are increasingly operating through tools, services and identities that organisations already trust.

Trellix says this makes contextual threat hunting essential, with AI helping process telemetry at scale while human analysts determine which anomalies warrant deeper investigation.

Key partners of Trellix

Amazon Web Services : Amazon Web Services (AWS) is one of Trellix’s key strategic partners, with the two companies combining Trellix’s threat detection capabilities with AWS cloud and generative AI infrastructure. AWS is led by CEO Matt Garman and is headquartered in Seattle, Washington. The companies have expanded their collaboration around AI-powered security, including Trellix solutions built on Amazon Bedrock.

Amazon Web Services : Amazon Web Services (AWS) is one of Trellix’s key strategic partners, with the two companies combining Trellix’s threat detection capabilities with AWS cloud and generative AI infrastructure. AWS is led by CEO Matt Garman and is headquartered in Seattle, Washington. The companies have expanded their collaboration around AI-powered security, including Trellix solutions built on Amazon Bedrock.

Google Cloud : Google Cloud is another strategic Trellix partner, with the companies working to integrate Trellix security capabilities across Google Cloud environments. Google Cloud is led by CEO Thomas Kurian and is headquartered in Mountain View, California. Their collaboration includes Google Cloud Partner Advantage and integrations designed to help security teams correlate cloud signals and identify threats more effectively.

Google Cloud : Google Cloud is another strategic Trellix partner, with the companies working to integrate Trellix security capabilities across Google Cloud environments. Google Cloud is led by CEO Thomas Kurian and is headquartered in Mountain View, California. Their collaboration includes Google Cloud Partner Advantage and integrations designed to help security teams correlate cloud signals and identify threats more effectively.

Telefónica Tech : Telefónica Tech is a strategic Trellix partner focused on combining cybersecurity, cloud and managed services. The company is headquartered in Madrid, Spain and is led by CEO Sofía Collado Echaure. Its collaboration with Trellix and AWS brings together threat detection, cloud infrastructure and managed security services for organisations across sectors including healthcare and financial services.

Telefónica Tech : Telefónica Tech is a strategic Trellix partner focused on combining cybersecurity, cloud and managed services. The company is headquartered in Madrid, Spain and is led by CEO Sofía Collado Echaure. Its collaboration with Trellix and AWS brings together threat detection, cloud infrastructure and managed security services for organisations across sectors including healthcare and financial services.

Rimini Street : Rimini Street is a major Trellix OEM partner, with its Advanced Database Security Suite integrating Trellix technology to protect enterprise data and security operations. The company is headquartered in Las Vegas, Nevada and is led by CEO, President and Chairman Seth Ravin. The partnership covers areas including database, endpoint, network and threat intelligence security, with the companies also developing custom security rules for customer environments

Rimini Street : Rimini Street is a major Trellix OEM partner, with its Advanced Database Security Suite integrating Trellix technology to protect enterprise data and security operations. The company is headquartered in Las Vegas, Nevada and is led by CEO, President and Chairman Seth Ravin. The partnership covers areas including database, endpoint, network and threat intelligence security, with the companies also developing custom security rules for customer environments

Amazon Web Services (AWS)

Amazon Web Services (AWS)

John Fokker Vice President, Threat Intelligence Strategy

Vice President, Threat Intelligence Strategy

Amazon Web Services (AWS)

Amazon Web Services (AWS)

AI Misalignment: How Anthropic's AI Hacked a Fourth Company Technology & AI

Veeam Research Warns of Shadow Agent Crisis in EMEA Technology & AI

Did ShinyHunters Breach the Florida DMV Database? Data Breaches

Top 10: AI-Powered Cybersecurity Solutions Technology & AI